发明名称 Method for accelerating hardware emulator used for malware detection and analysis
摘要 A method and system for accelerating malware emulator by using an accelerator. The accelerator allows for a potentially malicious component (i.e., process) containing dummy processes to be executed in a real CPU of a computer system using its operating memory. A special memory area is allocated for the process based on the memory requested by the process in the emulator. The state of the CPU and the memory is loaded in the emulator prior to executing the suspicious process. The system can be restored to its initial state in case of malicious actions performed by the process. The dummy instructions of the process are processed by the CPU at its own speed and as soon as the process performs a malicious instruction it is stopped by the emulator. The emulation process is accelerated to a speed of a regular CPU.
申请公布号 US7603713(B1) 申请公布日期 2009.10.13
申请号 US20090413907 申请日期 2009.03.30
申请人 KASPERSKY LAB, ZAO 发明人 BELOV SERGEH Y.
分类号 G06F11/00;G06F12/14;G06F12/16;G08B23/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址